6.4
CVSSv2

CVE-2008-6736

Published: 21/04/2009 Updated: 11/10/2018
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 645
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:P

Vulnerability Summary

Flat Calendar 1.1 does not properly restrict access to administrative functions, which allows remote malicious users to (1) add new events via calAdd.php, as reachable from admin/add.php, or (2) delete events via admin/deleteEvent.php. NOTE: this is only a vulnerability when the administrator does not follow recommendations in the product's security documentation.

Vulnerable Product Search on Vulmon Subscribe to Product

circulargenius flat calendar 1.1

Exploits

source: wwwsecurityfocuscom/bid/29662/info Flat Calendar is prone to multiple authentication-bypass vulnerabilities because it fails to perform adequate authentication checks An attacker can exploit these issues to gain unauthorized access to the application and make arbitrary changes to its configuration This may lead to further attac ...